Critical

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

Security Affairs
Actively Exploited

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in MLflow, identified as CVE-2026-64849, to its Known Exploited Vulnerabilities catalog. This flaw is categorized as a server-side request forgery (SSRF) with a high CVSS score of 9.3, indicating its potential severity. MLflow, which is used for machine learning lifecycle management, could allow attackers to manipulate server requests, potentially leading to unauthorized access or data exposure. Organizations utilizing MLflow should prioritize addressing this vulnerability to safeguard their systems. Given the critical nature of the flaw, it is essential for users to assess their exposure and implement necessary security measures promptly.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: MLflow
  • Action Required: Organizations should implement available patches for MLflow as soon as they are released and review their configurations to mitigate potential SSRF vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a […]

Impact

MLflow

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should implement available patches for MLflow as soon as they are released and review their configurations to mitigate potential SSRF vulnerabilities. Regularly updating to the latest version of MLflow is also recommended.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

New TCG guidance gives buyers a way to test PQC-ready TPM claims

Help Net Security

The Trusted Computing Group (TCG) has released new guidelines for Trusted Platform Modules (TPMs), which are essential components that secure a device's cryptographic keys and firmware integrity. These guidelines specifically address how TPMs can be deemed quantum-safe, a growing concern as quantum computing technology advances. Now, buyers can request proof from vendors that their TPMs meet these new standards, ensuring they are prepared for future quantum threats. This is significant for companies looking to protect their data from potential quantum attacks, as it provides a way to verify the security claims made by manufacturers. The move aims to enhance the overall security landscape as businesses transition to quantum-resistant technology.

Aug 25, 2026

ShinyHunters claims social engineering attack against ReliaQuest

SCM feed for Latest

A group known as ShinyHunters claims to have executed a social engineering attack against ReliaQuest. The attackers targeted employees by calling them and attempting to deceive them into visiting a fraudulent single sign-on (SSO) page. This fake page was hosted on a lookalike domain, reliaquest[.]claims, designed to mimic the legitimate ReliaQuest site. Such tactics can lead to credential theft and unauthorized access to sensitive company data. This incident raises concerns about the effectiveness of security training and awareness among employees, as social engineering remains a prevalent threat in cybersecurity.

Aug 24, 2026

WordPress plugin vulnerabilities allow admin account takeover

SCM feed for Latest

Researchers have identified two vulnerabilities in WordPress plugins, tracked as CVE-2026-61979 and CVE-2026-15981, that can be exploited together to bypass authentication and potentially take over admin accounts. This poses a significant risk to users of affected plugins, as attackers could gain unauthorized access to sensitive areas of WordPress sites. The vulnerabilities are particularly concerning for website administrators who may not be aware of these security flaws. It's crucial for users to check if their plugins are affected and take appropriate action to secure their sites, especially since the potential for exploitation exists. Prompt updates and vigilance are key to maintaining site security in light of these findings.

Aug 24, 2026

Developer alleges Alibaba uses audio fingerprinting for web tracking

SCM feed for Latest

Matt Callaghan, a software engineer, has raised concerns that Alibaba's website may be using audio fingerprinting techniques for tracking users. He found that the site employs obfuscated audio scripts that create a waveform and analyze its output, which could allow the company to monitor user behavior in a way that bypasses traditional tracking methods. This discovery raises significant privacy issues, as it suggests that users may be unwittingly tracked through audio signals emitted from their devices. The implications are serious, especially for individuals who value their privacy online. The use of such techniques could lead to increased scrutiny from regulators and may prompt users to reconsider their interactions with the site.

Aug 24, 2026

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

darkreading

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent three-day deadline for agencies to address a serious vulnerability in Zimbra, identified as CVE-2026-73570. This flaw enables attackers to take complete control over a user's communications, posing a significant risk to organizations using this software. The vulnerability could lead to unauthorized access to sensitive information and disrupt business operations. As Zimbra is widely used for email and collaboration, the implications of this vulnerability are considerable, affecting both public and private sector entities. Agencies are urged to act quickly to implement the necessary patches to mitigate this risk.

Aug 24, 2026

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

BleepingComputer

A vulnerability in Calix GS7 XGS residential routers, specifically the GS5239XG model, has been discovered, allowing attackers to bypass Network Address Translation (NAT) settings. This flaw enables remote, unauthenticated users to set up port-forwarding rules, which could expose internal devices on a user's local network to the public internet. The issue affects multiple broadband providers in the U.S. and poses significant risks as it could lead to unauthorized access to sensitive devices within homes. As of now, the vulnerability remains unpatched, leaving users at risk of potential exploitation unless action is taken to secure their networks. It's crucial for users of these routers to remain vigilant and consider disabling remote management features until a fix is provided.

Aug 24, 2026